/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Symantec report: instances of cryptojacking rose 8,500% in Q4 2017, partly due to easy-to-operate coin mining apps, coin mining up 34,000% in 2017

Where the money is, the thieves will follow  —  Instances of computers hijacked to mine cryptocurrency, a practice known as cryptojacking …

The Verge Shannon Liao

Context & Ripple Effects

Symantec's numbers put hard figures on a wave that had been building all quarter: [[a:926618|more than 4,200 websites, including USCourts.gov and UK NHS services, were already infected through a hacked plugin]] by February, and days after this report Krebs published a deep look at Coinhive, the JavaScript service that made hijacking visitors' CPUs nearly effortless. The 8,500% quarterly jump is what happens when coin mining apps become turnkey tools.

The arc continues through 2018: illicit mining surged another 459% year-over-year, tied partly to the leaked EternalBlue exploit, and an analysis of over 629,000 samples found at least 5% of all Monero in circulation was mined with malware — confirming Monero as cryptojacking's payout rail. By Q3, Malwarebytes saw malicious mining fall 26% even as business-targeted trojans jumped, hinting the boom was already peaking.

First-order effects

  • Businesses and consumers whose machines are hijacked pay directly in degraded performance and electricity costs, while Symantec and rival security vendors see detection of coin-mining payloads become a core product requirement almost overnight.

Second-order effects

  • Turnkey services like Coinhive collapse the skill barrier, pulling low-technical criminals into mining at scale and concentrating payouts in privacy coins like Monero, which becomes the de facto settlement layer for stolen hashpower.

Third-order effects

  • Cryptojacking establishes passive, victim-funded revenue as a criminal business model distinct from ransomware's one-shot extortion — but Malwarebytes' Q3 decline suggests it is price-cyclical, with attackers rotating back toward direct business attacks when margins compress.

The trend: Cryptocurrency crime industrializes around whatever is easiest to monetize — first hijacked compute via turnkey mining tools, then large-scale exchange hacks — with attacker effort tracking coin prices and available exploits.